How Does the Iranian Chosen Brick Spyware Campaign Work?

Article Highlights
Off On

The digital landscape of state-sponsored espionage has undergone a fundamental shift toward the weaponization of human psychology, as evidenced by the persistent Chosen Brick campaign. Orchestrated by the Iranian Ministry of Intelligence and Security, this operation has systematically targeted high-profile dissidents, journalists, and activists who live in exile across various Western nations. Since the middle of 2025, the campaign has matured into a sophisticated infrastructure designed to dismantle the digital and physical safety of those who challenge the status quo. Unlike conventional threats that prioritize technical exploits, this mission thrives on the slow cultivation of trust and the deliberate manipulation of social interactions. It represents a broader trend where intelligence services utilize highly personalized malware, dubbed Heavygram, to bridge the gap between digital surveillance and real-world harassment. By focusing on specific individuals rather than large organizations, the operators maintain a low profile while achieving deep, invasive access into the private lives of their targets.

Strategic Deception: The Psychology of Social Engineering

A defining characteristic of this campaign is the extensive social engineering phase that precedes any technical attack, demonstrating a level of patience rarely seen in automated phishing. Operators invest weeks or even months in researching a target’s background, professional interests, and personal affiliations before initiating contact on encrypted platforms like WhatsApp or Telegram. These initial interactions are often masqueraded as technical support requests from the messaging platforms themselves or as messages from established professional acquaintances. By engaging in long-form conversations that appear entirely benign, the attackers successfully bypass the natural skepticism that often protects high-risk individuals from sudden digital intrusions. This rapport-building process is critical because it conditions the victim to expect and trust future file transfers, effectively turning a human relationship into a vector for malware delivery. The psychological investment ensures that the eventual payload is received within a context that discourages any immediate suspicion or scrutiny.

Establishing Trust: Posing as a Legitimate Interlocutor

The deception deepens as the attackers employ contextually relevant lures designed to trigger a sense of professional or personal urgency within the target. For instance, dissidents have received files disguised as medical MRI scans showing degenerative conditions, or installers for specialized software like RunwayML and Pictory. When the victim executes the file, the malware maintains the illusion of legitimacy by displaying a functional decoy, such as a real medical image or a convincing login page, while the spyware installs in the background. This dual-action mechanism ensures that the victim remains unaware of the infection, believing they have simply opened a legitimate document or application. By using files that the target expects to see, the operators minimize the chance of the victim reporting the interaction to security professionals. This reliance on human-centric intelligence gathering allows the Iranian actors to bypass automated defense systems that typically flag generic or mismatched file types.

Delivering the Payload: Contextual Lures and Malware Delivery

One of the most alarming tactics identified in this campaign is the deliberate redirection of victims toward their personal hardware when professional security measures interfere. If an initial attempt to infect a work computer fails or appears likely to trigger enterprise-level security alerts, the attackers explicitly guide the victim to open the file on a home laptop. This strategy exploits the “blind spot” where professional-grade monitoring and endpoint protection are typically absent, allowing the malware to operate without interference. By understanding a journalist’s or activist’s daily workflow, the attackers identify the moments when a target is most vulnerable and least protected by corporate defenses. This transition from a secure environment to an unmonitored personal device represents a sophisticated understanding of modern cybersecurity architecture. It highlights how state actors adapt their methods not just to technical barriers, but to the behavioral patterns and environmental shifts of their specific human targets.

Technical Infiltration: Evasion and Surveillance Tactics

The technical architecture of the Chosen Brick spyware, also known as Heavygram, is specifically engineered for comprehensive surveillance and long-term persistence on infected machines. Once the malware gains a foothold, it achieves persistence by modifying registry keys and creating its own exclusions within Microsoft Defender to avoid detection by standard antivirus scans. Its capabilities are extensive, ranging from listing all running processes to activating the device’s microphone for secret audio recording and capturing real-time screenshots of the user’s activity. This level of access allows the Iranian Ministry of Intelligence and Security to monitor every digital move the victim makes, effectively turning their own computer into a surveillance outpost. The malware is designed to be lightweight and modular, allowing attackers to deploy specific payloads depending on the information they seek to gather. This modularity ensures that the infection remains difficult to analyze, as the full suite of malicious tools is rarely deployed at once.

Advanced Surveillance: The Trojanized Messaging Stack

A particularly invasive technique documented in recent reports involves the systematic harvesting of encrypted communication data directly from the victim’s web browsers. The malware is capable of stealing session data for platforms like WhatsApp and Telegram, allowing the attackers to bypass end-to-end encryption by accessing the messages at the endpoint. In some instances, the spyware goes as far as killing the legitimate WhatsApp desktop process and replacing it with a trojanized version that monitors communications in real-time. This allows the user to continue using the application without noticing any change in functionality, while every sent and received message is simultaneously exfiltrated to the attackers. Furthermore, specific payloads have been observed dumping entire Outlook mailboxes, including all attachments, into password-protected archives for clandestine extraction. This total visibility into the victim’s personal and professional correspondence provides the Iranian state with a comprehensive map of the target’s network and activities.

Infrastructure Control: Utilizing Encrypted Bots for Extraction

To manage the massive influx of stolen data while maintaining operational security, the campaign utilizes unique Telegram bot IDs for every individual victim infected. This compartmentalization ensures that if a single infection is discovered and the associated command-and-control infrastructure is blocked, the rest of the victim network remains secure from discovery. This tactic prevents “cross-contamination” and makes it significantly harder for cybersecurity investigators to map the full scale of the Iranian operation across different regions. The use of legitimate messaging platforms for command-and-control traffic also helps the malware blend in with normal network activity, as many users regularly use Telegram for personal or work communication. This strategy reflects a high degree of operational maturity, as it prioritizes the longevity of the campaign over the speed of data collection. By isolating each victim, the operators can maintain their surveillance for years, slowly gathering intelligence that can eventually be used for more aggressive actions.

Mitigating the Threat: Lessons From the Spyware Response

Security experts recommended that individuals at risk should transition to hardware-based security keys and maintain strict device isolation to mitigate these persistent threats. The analysis of the Chosen Brick campaign highlighted that technical defenses alone were insufficient when the attack vector was a trusted human interaction. Organizations improved their protocols by educating staff on the dangers of moving professional communications to personal hardware where monitoring was absent. By documenting these tactics, intelligence agencies provided a roadmap for identifying future surveillance attempts before they escalated into physical violence. It was observed that the most resilient targets were those who treated unsolicited file transfers with extreme caution, regardless of the sender’s perceived identity. Moving forward, the integration of behavioral analysis and enhanced endpoint protection became the standard for protecting those vulnerable to transnational repression. These defensive strategies successfully reduced the impact of state-sponsored spyware by narrowing the window of opportunity for attackers to exploit personal blind spots.

Explore more

OLRB Clarifies Workplace Harassment Investigation Standards

Employers who fail to interview relevant witnesses identified in an initial complaint may find their entire harassment investigation invalidated by regulatory bodies for a lack of procedural thoroughness. This warning stems from a pivotal ruling by the Ontario Labour Relations Board, which recently clarified the murky legal requirements surrounding workplace harassment inquiries. Under the Occupational Health and Safety Act, employers

How Do We Secure the Modern SaaS Attack Surface?

Transitioning to an integrated governance model is essential for preventing security gaps that naturally occur between siloed detection and recovery systems in the cloud. The shift from on-premise infrastructure to these expansive cloud-centric models has fundamentally dissolved the traditional security perimeter that once defined corporate safety. As organizations now manage an average of 100 different software-as-a-service applications, the obsolete walled

Can the Middle East Withstand the Massive Surge in Ransomware?

Modern cyber-warfare in the Middle East is being defined by a transition toward high-pressure attacks on sectors that impact the general population. This shift marks a dramatic escalation in the regional threat landscape, where the Gulf states have moved from being secondary targets to the primary focus of global cyber-criminal organizations. Data from recent investigations reveals a staggering rise in

How to Choose the Best AI API Platforms for Developers in 2026?

Transitioning between different AI providers becomes prohibitively expensive if a codebase must be rewritten for every specific model integration. The technological landscape of 2026 has fundamentally shifted the way developers approach artificial intelligence. No longer is an AI strategy defined by the implementation of a single Large Language Model (LLM); instead, modern application development requires a sophisticated integration of multi-modal

OpenAI Tests Sponsored Agents to Transform Digital Advertising

Marketers are now facing a strategic ownership tradeoff as they weigh the convenience of keeping users within an AI ecosystem against the loss of direct first-party behavioral data. OpenAI is currently refining its monetization strategy by testing “Sponsored Agents” within ChatGPT, representing a fundamental departure from the click-through models that have defined the internet. For decades, digital ads served as